How to rule out Global IP Blacklist?

jack.brown

Silver Partner
Advanced Certified
Joined
Aug 17, 2022
Messages
4
Reaction score
2
Hi all,

We have an overseas user who is often unable to gain access to the 3CX system without using VPN services.

I am conscious that many VPN services (and their associated IP addresses) will be regularly abused to launch attacks on 3CX systems, and will therefore be commonly found in the Global IP Blacklist.

I was wondering if there is a way to determine if/when incoming connections are being rejected because they're listed on the Global IP Blacklist, or alternatively, to look up an IP address against the database (although I appreciate why the latter may not be possible).

For context, the user is connecting from Poland to the UK, and there are no IP-based firewall restrictions on ports 5001 or 5090.
They exclusively use mobile / web apps.
They can log into the system and make outbound calls while using their VPN to the UK, however they show as unregistered and cannot receive calls.
With the VPN disabled, they cannot access the system at all.

I understand that the cause is more likely to be outbound restrictions on their VPN and/or their local WAN connection in Poland, however, it would be useful to find a way to rule out the Global IP Blacklist when diagnosing this issue and with future issues too.

Any insight would be very much appreciated.
 
They can log into the system and make outbound calls while using their VPN to the UK, however they show as unregistered and cannot receive calls.
With the VPN disabled, they cannot access the system at all.
They wouldn't be able to log in if blacklisted.

If they are using the web client have they (and everyone else) enabled notifications in the browser? (the bell icon in the upper left)

The global blacklist can be disabled via Advanced > Anti-Hacking > Automatic Global IP Blacklist.
 
They wouldn't be able to log in if blacklisted.

If they are using the web client have they (and everyone else) enabled notifications in the browser? (the bell icon in the upper left)

The global blacklist can be disabled via Advanced > Anti-Hacking > Automatic Global IP Blacklist.

Hi Steve, thank you for your reply, this makes a lot more sense to me now that I've had a proper night's sleep.
Browser notifications definitely sound like the issue here, I've run into similar symptoms with other customers running later PBX versions
I'll go ahead with that - appreciate the sanity check
 

Latest Posts

Forum statistics

Threads
111,962
Messages
589,996
Members
164,867
Latest member
swegner